OS Command Injection in CVS - CVE-2017-12836

 

OS Command Injection in CVS - CVE-2017-12836

Published: June 25, 2020


Vulnerability identifier: #VU29260
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12836
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when processing characters in the URL of a remote repository within SSH client.  A remote attacker can trick the victim to use a specially crafted connection URL, inject and execute arbitrary OS commands on the client's system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

CVS
Gentoo Linux
Fedora
cvs (Alpine package)
cvs

How to mitigate CVE-2017-12836

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

cvs (Alpine package) - update to 1.12.12-r0
cvs - addressed in versions 1.11.23-41.fc25, 1.11.23-42.fc26

External References

Related Security Bulletins